The embodiment of the invention provides an
intranet security operation and maintenance method and device based on a
bastion host, a medium and a program product, and relates to the technical field of operation and
maintenance management. The method comprises the following steps: in response to a connection request actively initiated by a zero-trust proxy
client, establishing an end-to-end encrypted
application layer tunnel between a zero-trust
proxy server and the zero-trust proxy
client under the condition that bidirectional
authentication is passed; acquiring context information corresponding to the operation and maintenance terminal, and determining a dynamic
authorization strategy based on the context information; and performing operation and
maintenance management and control on the operation and maintenance operation of the operation and maintenance terminal based on the dynamic
authorization strategy, and transmitting operation and maintenance traffic generated between the operation and maintenance terminal and the
intranet resource side through the
application layer tunnel. According to the embodiment of the invention, the zero-trust
system model taking the internal resource side as the active connection end is constructed, and the dynamic
authorization strategy is generated by acquiring the related context information in real time, so that the security of internal network operation and maintenance is greatly improved.